Bug 847620 - [FEAT] NFSv3 Authorization rpcsec_gss + krb5 (cluster aware credential cache)
Summary: [FEAT] NFSv3 Authorization rpcsec_gss + krb5 (cluster aware credential cache)
Keywords:
Status: CLOSED DEFERRED
Alias: None
Product: GlusterFS
Classification: Community
Component: nfs
Version: mainline
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: GlusterFS Bugs list
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 852953 854182 864864
TreeView+ depends on / blocked
 
Reported: 2012-08-13 07:29 UTC by Krishna Srinivas
Modified: 2014-10-26 09:33 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
: 864864 (view as bug list)
Environment:
Last Closed: 2014-10-25 17:29:34 UTC
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Embargoed:


Attachments (Terms of Use)

Description Krishna Srinivas 2012-08-13 07:29:52 UTC
Support for rpcsec_gss + krb5 based authentication for NFSv3.

Comment 1 Anand Avati 2012-08-30 05:32:00 UTC
We should not target this specifically for NFSv3. Introducing this auth mode should be usable in RPC between protocol client/server - specifically for usage with gfapi.

Comment 3 Niels de Vos 2014-10-25 17:29:34 UTC
This will be supported when nfs-ganesha is used in combination with Gluster. There currently is no intention to add support for rpcsec_gss/krb5 to Gluster/NFS.

Comment 4 Alastair Neil 2014-10-25 20:30:00 UTC
sorry does this mean there is no intention to provide secure rpc to gluster sharing at all except through third party layers?

Comment 5 Niels de Vos 2014-10-26 09:33:38 UTC
(In reply to Alastair Neil from comment #4)
> sorry does this mean there is no intention to provide secure rpc to gluster
> sharing at all except through third party layers?

This bug/feature was for signed/encrypted support for NFSv3, for which we currently do not have a plan to add. nfs-ganesha is a very feature complete NFS-server and will get more attention to improve support for Gluster.

There is support for SSL encrypted communication between clients and servers (see bug 1114604 for more details). I think a feature request for krb5 signed/encrypted GlusterFS communication would make sense and could get accepted. There does not seem to be such a request yet (or at least I can not find it), so you may want to file a new bug for it against the rpc component:
- https://bugzilla.redhat.com/enter_bug.cgi?product=GlusterFS&component=rpc


Note You need to log in before you can comment on or make changes to this bug.